Privacy Policy

Effective 18 July 2026

1. Scope and controller

This policy explains how Panacea Technologies ("Panacea") processes personal data when you use the Panacea platform. For platform account data, Panacea is the data controller within the meaning of Kenya's Data Protection Act, 2019. Institutions you interact with (a clinic, a school, a bank, a government agency, a store) are controllers of the records they hold about you; Panacea processes those records on the basis of your explicit consent grants.

2. What we collect

Account and identity data (name, email, phone, date of birth, national ID where you provide it or link a government identity), transaction data (orders, payments, deliveries), records shared with you or by you inside modules you use (health, education, finance, government), device and log data, and support communications. Sensitive identifiers and clinical data are encrypted at rest; access to your data is written to an audit log you can inspect in the portal.

3. Why we process it

To operate your account and the Services (contract); to verify identity and prevent fraud (legal obligation and legitimate interest); to move specific data between institutions when — and only when — you grant consent, which you can revoke at any time in Portal → Access permissions; to send service notifications (our outbound emails and texts are deliberately content-free — the substance stays in-app); and to comply with law, including tax and financial-records obligations.

4. Sharing

We share personal data with: institutions you transact with or grant consent to; payment providers (e.g. Safaricom M-Pesa, card processors) to process payments you initiate; delivery partners for shipments; government identity providers when you choose to link them; and infrastructure providers under data-processing agreements. We do not sell personal data.

5. Your rights

Under the Data Protection Act, 2019 you have the right to be informed, to access your data, to rectification, to erasure of data we have no lawful basis to retain, to object to or restrict processing, and to data portability. In the portal: Privacy & data lets you export your data and request account deletion; Access permissions lets you review and revoke consent grants and see the access audit log. You may also lodge a complaint with the Office of the Data Protection Commissioner (www.odpc.go.ke).

6. Deletion and retention

When you request account deletion, your account is deactivated immediately, all active sessions are ended, and your profile stops being visible in the Services. Records we are legally required to keep — financial transaction records, tax records, and audit trails required by the DPA — are retained for the statutory period and then erased. Institution-held records (e.g. your clinical record at a hospital) remain governed by that institution's retention obligations.

7. Security

Personal identifiers and sensitive fields are encrypted at rest, transport is TLS-only, access is role- and consent-gated with institution-level isolation, and changes to records carry an audit trail. No system is perfectly secure; if a breach affecting your data occurs we will notify you and the ODPC as the DPA requires.

8. International transfers

Where processing happens outside Kenya, we ensure the DPA's conditions for cross-border transfer are met, including appropriate safeguards with our infrastructure providers.

9. Changes and contact

Material changes to this policy are announced in-app before they take effect. Data protection questions and rights requests: privacy@panaceatechnologies.ai.